© 2025-2026 PySpect
First version without a known vulnerability: 6.5.8
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Fixed in: 6.5.8
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
Fixed in: 6.5.8
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
Fixed in: 6.5.8
Tornado: Quadratic DoS via Crafted Multipart Parameters
Fixed in: 6.5.3
Tornado: Quadratic DoS via Repeated Header Coalescing
Fixed in: 6.5.3
Tornado vulnerable to Header Injection and XSS via reason argument
Fixed in: 6.5.3
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
Fixed in: 6.5.7
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
Fixed in: 6.5.6
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
Fixed in: 6.5.6
Tornado has out-of-bounds memory access via C extension
Fixed in: 6.5.6
Tornado is vulnerable to DoS due to too many multipart parts
Fixed in: 6.5.5
Tornado has incomplete validation of cookie attributes
Fixed in: 6.5.5
Tornado vulnerable to excessive logging caused by malformed multipart form data
Fixed in: 6.5
Tornado has an HTTP cookie parsing DoS vulnerability
Fixed in: 6.4.2
Tornado has a CRLF injection in CurlAsyncHTTPClient headers
Fixed in: 6.4.1
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
Fixed in: 6.4.1
Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengths
Fixed in: 6.3.3
Open redirect in Tornado
Fixed in: 6.3.2
Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)
Fixed in: 3.2.2, 1c36307463b1e8affae100bf9386948e6c1b2308
Tornado CRLF injection vulnerability
Fixed in: 2.2.1